WordPress security by component
AR for WooCommerce
Plugin description
AR for WooCommerce is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jul 03, 2026; the highest published CVSS base score is 10.
Plugin slug:
ar-for-woocommerceLatest vulnerability
CVE-2026-14352: AR for WooCommerce: Filesystem traversal
AR for WooCommerce is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 8.40.
| Safe version |
|
||
|---|---|---|---|
| Jul 03, 2026 |
CVE-2026-14352
AR for WooCommerce: Filesystem traversal
AR for WooCommerce is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 8.40.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Oct 30, 2024 |
CVE-2024-50510
AR For Woocommerce: Dangerous file upload
AR For Woocommerce is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE10.0
NVDPending
|